CVE-2019-5935
MEDIUMCybozu Garoon 4.0.0-4.10.1 - Authenticated Access Restriction Bypass via User Information Item Function
Title source: llmDescription
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN58849431/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/35497/
Scores
CVSS v3
4.3
EPSS
0.0018
EPSS Percentile
39.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Details
Status
published
Products (1)
cybozu/garoon
4.0.0 - 4.10.1
Published
May 17, 2019
Tracked Since
Feb 18, 2026